4.1.3 “Check” – Process Groups
The “Check” part of the lifecycle contains one
process group: Live Network Risk Management
Processes, with 2 processes. The Monitoring process
allows the network to be monitored for emerging
risks, effectiveness of risk control measures, and
accuracy of original estimations of risk. The Event
Management process ensures that adverse events
during the operational phase are managed correctly.
4.1.4 “Act” – Process Groups
The “Act” part of the lifecycle contains one process
group: Change/Release Management &
Configuration Management which includes 3
processes. The purpose of the Change/Release &
Configuration Management process is to ensure that
a documented Change Release Process is in place
and that risk management activities take place
during the Change Release process. Acceptability of
the change is based on the results of the risk
management activities which are performed as part
of the Change Release process. All changes to the
system must be reflected in the current
Configuration Management information held with
regard to the network which is carried out as part of
this process. The second process within this group is
the Decision on how to apply Risk Management, the
purpose is to ensure that a policy is in place to allow
organisations to consider the nature of the change
that is required to the medical IT network and to
assess if the change should be carried out under a
change permit or by initiating a medical IT network
project. The final process within the group is
concerned with risk management activities during
the Go-Live phase of the lifecycle. The purpose of
the process is to allow the responsible organisation
to manage the transition of the IT network to the live
environment and to allow the responsible
organisation to manage the risk management
activities associated with the Go-Live phase of the
project.
5 FUTURE WORK
Future work in this area will focus on the extension
of the PRM with the addition of a measurement
framework to form the PAM. This PAM will then be
validated within the international standards
community and within a healthcare setting. An
assessment method will also be developed.
ACKNOWLEDGEMENTS
This research is supported by the Science
Foundation Ireland (SFI) Stokes Lectureship
Programme, grant number 07/SK/I1299, the SFI
Principal Investigator Programme, grant number
08/IN.1/I2030 (the funding of this project was
awarded by Science Foundation Ireland under a co-
funding initiative by the Irish Government and
European Regional Development Fund), and
supported in part by Lero - the Irish Software
Engineering Research Centre (http://www.lero.ie)
grant 10/CE/I1855.
ITIL® is a registered trade mark of the Cabinet
Office. TIPA® is a Registered Trade Mark of the
CRP Henri Tudor.
REFERENCES
Barafort, B., Betry, V., Cortina, S., Picard, M., St Jean,
M., Renault, A., Valdés, O. & Tudor, P. R. C. H.
2009. ITSM Process Assessment Supporting ITIL :
Using TIPA to Assess and Improve your Processes
with ISO 15504 and Prepare for ISO 20000
Certification, Zaltbommel, Netherlands, Van Haren.
Barafort, B., Renault, A., Picard, M. & Cortina, S. 2008. A
transformation process for building PRMs and PAMs
based on a collection of requirements – Example with
ISO/IEC 20000. SPICE Nuremberg, Germany.
Cooper, T., David, Y. & Eagles, S. 2011. Getting Started
with IEC 80001: Essential Information for Healthcare
Providers Managing Medical IT-Networks, AAMI.
IEC 2010. IEC 80001-1 - Application of Risk
Management for IT-Networks incorporating Medical
Devices - Part 1: Roles, responsibilities and activities.
Geneva, Switzerland: International Electrotechnical
Commission.
ISO/IEC 2003. ISO/IEC 15504-2:2003 - Software
engineering — Process assessment — Part 2:
Performing an assessment. Geneva, Switzerland.
ISO/IEC 2010. ISO/IEC TR 24774:2010 - Systems and
software engineering — Life cycle management —
Guidelines for process description. Geneva,
Switzerland.
ISO/IEC 2011a. ISO/IEC 20000-1:2011 - Information
technology —Service management Part 1: Service
management system requirements. Geneva,
Switzerland.
ISO/IEC 2011b. ISO/IEC PDTR 15504-8 - Information
technology -- Process assessment -- Part 8: An
exemplar process assessment model for IT service
management. Geneva, Switzerland.
National Cybersecurity and Communications Integration
Center 2012. Attack Surface: Healthcare and Public
Health Sector.
The Cabinet Office 2011. ITIL 2011 - Summary of
Updates. Norfolk, England: Crown Copyright.
HEALTHINF2013-InternationalConferenceonHealthInformatics
304